Known vulnerabilities are managed to prevent harm to essential functions. Partially achieved: current understanding of exposure to public vulnerabilities, announced vulnerabilities tracked and prioritised with externally exposed ones mitigated promptly, temporary mitigations for unsupported technology while migration is pursued, and regular testing of vulnerabilities. Achieved: all announced vulnerabilities tracked and mitigated promptly, regular testing verified by third-party testing, and supported software, firmware and hardware maximised.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.